T09 · Insecure Skill Coding Practices
- Location
SKILL.md:211- Finding
Blind Signing and Execution of Remotely Generated Financial Calldata
- Content
View full analysis
\ --chain \ --input-data \ --value \ --biz-type defi ``` EVM (XLayer): ```bash onchainos wallet contract-call \ --to \ --chain 196 \ --input-data \ --value \ --biz-type defi ``` Solana: ```bash onchainos wallet contract-call \ --to \ --chain 501 \ --unsigned-tx \ --biz-type defi ``` `contract-call` handles TEE signing and broadcasting internally — no separate broadcast step needed. ``` The corresponding remote response fields are documented in `references/cli-reference.md:249-258`: ```text **Return fields** (`data.dataList` array — execute in order): | Field | Type | Description | |---|---|---| | `dataList[]` | Array | Ordered list of transactions to execute | | `dataList[].callDataType` | String | Operation type: `APPROVE`, `DEPOSIT`, `SWAP,DEPOSIT`, `WITHDRAW`, `WITHDRAW,SWAP` | | `dataList[].from` | String | Sender address (user wallet) | | `dataList[].to` | String | Target contract address | | `dataList[].value` | String | Native token value (e.g. `"0x0"` for no native transfer) | | `dataList[].serializedData` | String | Transaction data: EVM=hex (0x prefix), Solana=base58, Sui=base64 BCS | | `dataList[].originalData` | String | ABI metadata JSON (EVM only) | ``` ### Technical Analysis The skill instructs the Agentic Wallet to sign and broadcast ...[truncated 3298 chars]- Remediation
View remediation
